Zyxel ZyWALL USG 50 [9/185] Zywall usg support notes

Zyxel ZyWALL USG 50 [9/185] Zywall usg support notes
ZyWALL USG Support Notes
9
All contents copyright (c) 2010 ZyXEL Communications Corporation.
3. Then USG will check whether there‟s DNAT (Destination NAT) rule set, if there
is, it will translate the destination address according to the DNAT rule. If there‟s
not, USG will remain the original destination address. Usually from traffic sent
from intranet to outside, there‟s no DNAT rule set.
4. The traffic is sent to the routing procedure. USG decide where it should send the
traffic to, and via which interface.
5. The traffic is sent to the firewall processing stage. If according the firewall rule,
the traffic is allowed, USG will allow the traffic to pass, if it‟s set to Block, the
USG will drop the traffic, and generates a log if the firewall rule is set to log.
6. The traffic is sent to the ADP processing stage. USG will perform ADP checking
according to ADP rules, and ADP signatures. If the traffic is detected as anomaly
attack, the USG will block/log the traffic according to the ADP signatures.
7. The traffic is sent to the IDP processing stage. USG will perform IDP checking
according to IDP rules, and IDP signatures. If the traffic is detected as intrusion
attack, the USG will block/log the traffic according to the IDP signatures.
8. The traffic is sent to Application Patrol processing stage. USG will check the
traffic application layer to determine its class according to relative IDP signatures.
If traffic matches some application class, USG will decide how to handle the
traffic according to the App Patrol rules.
9. Traffic is sent to Content Filtering processing stage if the traffic is web traffic.
USG check what action it should take according to Content Filtering rules.
10. The traffic is sent to Anti-Virus processing stage. USG will examine the traffic
with AV signatures. If virus is detected, it will give corresponding action
according to AV setting.
11. The traffic is sent to Anti-Spam processing stage if it is mail traffic (SMTP, POP3),
then gives corresponding action according to AS settings.
12. The traffic is sent to SNAT procedure. USG will map the traffic‟s source address
according to SNAT rules (outgoing interface, customized address, NAT 1:1
address, etc, which is to be discussed later).
13. The traffic is sent to Bandwidth Management procedure. USG will allocate
bandwidth to the traffic if corresponding BWM rule is set.
14. The traffic will be fragmented if the frame is larger than the interface‟s MTU
setting.
15. The traffic is finally sent out.
1.1.2. Routing priority
Understanding Routing Priority in USG ZyWALL helps a lot for you to correctly set

Содержание

Похожие устройства

Скачать